s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-b481cc2e88ab19b63fca837aef5d80b961659621db8650ee307305062b4eeb41 high

📛 Threat Title

Mirai: data_x86_64

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 396640 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:33:45.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 b481cc2e88ab19b63fca837aef5d80b961659621db8650ee307305062b4eeb41

IOC database

Type
hash_sha256
Value
b481cc2e88ab19b63fca837aef5d80b961659621db8650ee307305062b4eeb41
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 b59686479528d4aabc65f98ab2ee479b

IOC database

Type
hash_md5
Value
b59686479528d4aabc65f98ab2ee479b
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 21308bc38b389ed859040ca70c776995a75a2642

IOC database

Type
hash_sha1
Value
21308bc38b389ed859040ca70c776995a75a2642
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 396640 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:33:45.

Remediations (10)

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:github.com

    This repository is a treasure trove of botnet implementations, ranging from infamous Mirai variants to unique configurations and enhancements. Below is a brief description of the main directories: - maxamin/Botnets

  • web:rruzi.github.io

    In-depth Analysis of a New Mirai Variant 7 minute read Published: December 28, 2024 I. Background Recently, NSFOCUS [1], National Cyber Security Center (NCSC) [2], and 360 Security Brain [3] detected a batch of botnet samples that integrate the TEA algorithm for encryption based on the leaked source code of Mirai , targeting IoT/Linux devices of various architectures such as ARM, MIPS, and x86 ...

  • web:trainsec.net

    The anti-virus checks labeled it as " Mirai ," matching what I found in the documentation, sandbox analyses, and community threat intelligence sources. Mirai is known to compile variants for multiple architectures (ARM, MIPS, x86, x64, etc.), making it adaptable and widespread.

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.joesandbox.com

    2 other IPs or domains Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file mirai .x86-64.elf started dash rm started

  • web:www.pwndefend.com

    We pulled the x86-64 build and analysed it statically — no execution. It is a lean (67 KB) statically-linked, stripped ELF with the .ctors /.dtors layout and encoded-string table characteristic of the Mirai family.

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.techtimes.com

    Tengu botnet, a newly disclosed Mirai variant, weaponizes the hardware watchdog timer in routers and IP cameras to force a reboot when a responder kills the process — erasing forensic evidence ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.